Effective Risk Reporting
An important element of risk management is related to risk reporting i.e., how do you convey the results of the risk management process to management.
Starting with the end of the sentence “to management” means the reporting must be defined in such a way and with such content that management finds this relevant and valuable.
Dangerous Data
Over the years, I have advocated vigorously for the use of facts and data when analysing and assessing risks, uncertainties and levers. I fully stand by this and will continue advocating for using data as well as I firmly believe there really is no such thing as “qualitative analysis”.
Heat Maps and Risk Management
Heatmaps are commonly used as reporting and discussion tools in risk management. However, there are two different types/categories of heatmaps, only one of which is useful.
When Risk Maps become Risk Traps
Let us step back and consider the process of collecting risk information for the purpose of communicating to senior management and the Board about the most important threats to their organization (that they may or may not be currently aware of) with sufficient credibility to cause them to sponsor further action.